Skyl Privacy Policy
This Privacy Policy describes how Vestgaard Construction Ltd. ("Skyl," "we," "us," or "our"), operating as Skyl, collects, uses, discloses, and protects your information when you use the Skyl mobile application (the "App") and any related services (together, the "Service"). The Service is a social and professional network for construction-trade professionals to share work, find jobs, message peers, build a portfolio, and join crews and clubs.
This policy explains our handling of personal information. We request permission or consent separately where required, and the choices below explain how to change optional processing.
1. Information We Collect
1.1 Information you provide
- Age confirmation. Your confirmation that you meet our 18+ eligibility requirement, the confirmation time, and policy version.
- Account credentials. Email address and/or phone number, and a password. Phone-number sign-up uses SMS one-time passwords (OTP) sent via Supabase Auth.
- Profile information. Username, full name or company name, bio, trade, location (free text), years of experience, hourly rate, profile image, banner image, account type (personal or company), and badges.
- About-me / business-card details. Optional work experience, languages, trade school, certifications (issuer, dates, credential ID, image), and optional contact email/phone that you choose to display on your portfolio or business card.
- Company / business profile. Company name, logo, profession, company size, hiring status, description, website, social links, services, and team members.
- User-generated content. Posts (text, images, videos), comments and replies, direct messages, crew chat messages, job-application messages, job listings, portfolio items (photos, PDFs, descriptions, tools, skills, project location), club posts, and feedback you submit through the in-app form.
- Job-related information. Job title, description, requirements, pay, location, and any cover message you submit when applying.
- Support information. Subject, category, message body, and contact email when you contact Skyl support.
1.2 Information collected automatically
- Usage and engagement data. Likes, comments, saves, follows, friend/crew memberships, job applications, post views, feed impressions, video watch events, and search queries (recent queries are stored only on your device).
- Presence data. A
last_seentimestamp updated approximately every two minutes while the App is in the foreground, when you have "Show Online Status" enabled. - Push notification token. A device token issued by Apple Push Notification service or Firebase Cloud Messaging, relayed through Expo Push, so we can deliver notifications.
- Approximate or precise location. When you enable Location Services in Settings and permit location access in iOS, the App can use your device position on the map. Weather is currently unavailable while we configure commercial service. The updated September 22 iOS build does not request GPS for weather or send coordinates to Open-Meteo. Earlier releases used coordinates for forecasts and stored a city-level cache locally; Open-Meteo states that its request logs may include coordinates and are retained for 90 days. Map positioning remains optional. Submitted place searches use the native geocoder (Apple on iOS), which processes search strings and coordinates; it does not require sharing your current GPS position for a typed search.
- Device and log data. App version, OS version, device model, language, and crash/performance logs that may be produced by the operating system or by Expo.
- Moderation records. When content is reported or scanned, we store the report reason, automated decision and scores, and any appeal you submit.
1.3 Information stored on your device
The App stores the following on your device using AsyncStorage:
- Your Supabase session tokens (access and refresh tokens) for login persistence.
- For multi-account switching: the user ID, email, display name, avatar, and session tokens for each saved account.
- Your per-user settings (notification preferences, privacy flags, location-services toggle, language, online-status toggle).
- Cached weather and news data, recent search queries, hidden message threads, and showcase layout preferences.
1.4 Sensitive information
We do not knowingly collect sensitive personal data such as government IDs, racial or ethnic origin, religious beliefs, health data, or biometric data. Please avoid posting sensitive documents or information that is unnecessary for using Skyl, including information about clients or coworkers without permission. Sensitive information may appear in user content despite this request; it remains subject to appropriate access, moderation and deletion handling. Contact us to report sensitive information that should be removed.
2. How We Use Your Information
We use your information to:
- Operate the Service. Create and authenticate accounts, display profiles, show feeds, reels, jobs, clubs, and crews, and sync content across devices.
- Enable communication. Deliver direct messages, crew chat, job-application threads, mentions, comments, and notifications.
- Personalize and rank content. Use your trade, follows, crew memberships, location, and engagement signals to rank feed posts, reels, jobs, and news.
- Provide hiring features. Display job listings, accept and track applications, and let employers contact applicants.
- Show weather and maps. Use your location (when enabled) for map positioning, and process submitted place searches through the native geocoder. Weather requests are currently disabled.
- Send push notifications. Notify you about likes, comments, mentions, follows, friend/crew/team invites, direct messages, job applications, and moderation actions. You can adjust or disable these in Settings.
- Maintain safety and enforce guidelines. Automatically scan text and media for policy violations, review reported content, warn, suspend, or ban accounts that violate our Community Guidelines, and respond to appeals. Child-safety reports may be reported to the National Center for Missing & Exploited Children (NCMEC) where required by law.
- Provide support. Receive and respond to support tickets and feedback, including by email.
- Aggregate analytics and product improvement. Analyze engagement patterns (post views, feed events, watch time) to improve ranking, surface bugs, and decide product direction. We do not use a third-party analytics SDK.
- Prevent fraud and abuse. Detect duplicate accounts, suspicious activity, and policy violations.
- Meet legal obligations. Comply with law enforcement requests where legally required, and meet tax and accounting obligations.
3. How We Share Your Information
3.1 With other users
- Public profile data (username, full name, profile image, banner, trade, bio, badges) is visible to authenticated users.
- Your posts, comments, and likes are visible according to the audience you choose (public, followers, club members, or crew members).
- Direct messages and crew chats are visible to participants.
- Job applications and job-application threads are visible to the applicant and the job poster.
- Online status (green/red dot, "last seen") is shown to other users when "Show Online Status" is enabled.
- Mentions and tags notify the user you mention or tag and disclose your username to them.
3.2 With service providers and processors
We share data with the following third parties that process data on our behalf:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication, database, realtime, edge functions, file storage | Account credentials, profile data, UGC, engagement, settings |
| Cloudflare (R2, Stream, Workers, Email Routing/Sending) | Media storage and CDN, video transcoding, transactional email | Media files, video files, email content, reply-to email |
| Expo (EAS Updates, Push) | OTA updates, push delivery | Push tokens, update metadata |
| Open-Meteo | Weather in earlier releases; disabled in this release pending commercial configuration | Previously submitted coordinates and provider request logs |
| Apple geocoding (iOS) | Submitted place searches and location labels | Search strings and coordinates |
| OpenStreetMap Nominatim | Geocoding in earlier releases; replaced in the updated September 22 iOS build | Previously submitted location search strings and coordinates |
| OpenAI | Automated text moderation (including posts, comments, profiles, jobs and messages) | Text content |
| Sightengine | Automated image and video moderation | Images, videos, associated media URLs and moderation results |
| Google AdMob | Optional in-feed ads (where enabled) | Ad interactions, IP address, device/SDK identifiers and diagnostic data; advertising identifier where permitted |
| CARTO / unpkg | Map tiles and map-rendering assets | IP address, requested tile/asset URLs and request/device metadata |
| Giphy | GIF search and delivery | GIF search terms, IP address and request/device information |
| Apple / Google | OS-level push delivery | Push tokens via APNs/FCM |
Providers process information under their applicable terms and privacy notices. Their role depends on the service: some act on our instructions, while advertising and other providers may also process information for their own disclosed purposes.
3.3 For legal and safety reasons
We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation or law-enforcement request; (b) protect the safety, rights, or property of Skyl, our users, or the public; (c) investigate or respond to suspected violations of our Community Guidelines; (d) detect, prevent, or otherwise address fraud, security, or technical issues; or (e) enforce our Terms.
3.4 We do not sell your data
We do not sell your personal information to third parties. Where we serve ads through Google AdMob, that activity may be considered "sharing" or "cross-context behavioral advertising" under some state laws; we apply the applicable consent and opt-out controls. Apple tracking permission is separate from other advertising privacy choices.
4. Your Choices and Controls
You can manage your data through the App's Settings screen and through system-level controls:
- Push notifications. Toggle each notification type or disable all in Settings, or disable notifications at the OS level.
- Location services. Turn Location Services on or off in Settings; the App will not access GPS when off, and the map will not request your current GPS position. Weather is currently unavailable in the updated build.
- Online status. Toggle "Show Online Status" in Settings; when off, your
last_seenis cleared and not displayed. - Private account. Enable "Private Account" to require approval of new followers and limit who can see your posts.
- Hidden message threads. Hide specific DM or crew conversations from your list without deleting them.
- Block users. Block other users from contacting you or viewing your content.
- Ad tracking. Use Apple's App Tracking Transparency prompt or Android settings to deny or revoke advertising identifier access. Settings → Ad privacy provides additional advertising privacy choices where available.
- Account deletion. You can request account deletion through the App or by contacting
team@skylstudios.com. Your login is removed immediately. Profile, posts, comments, messages, and personal data are deleted as soon as possible. Leftover media files or login records are purged within 30 days, subject to legal retention requirements. - Data export. You may request a copy of your personal data by emailing
team@skylstudios.com. - Withdraw consent. You can withdraw consent for optional data processing (location, push, online status, ads) at any time by adjusting the relevant setting.
4.1 How to turn off Push Notifications
Inside the App:
- Open the Skyl app.
- Tap your profile icon, then tap Settings (gear icon) in the top right.
- Under Notifications, toggle off any notification types you no longer want (likes, comments, mentions, follows, direct messages, crew messages, job applications, etc.).
- To disable all in-app push notifications at once, toggle off Push Notifications at the top of the Notifications section.
At the OS level (more thorough):
- iOS: Open the iOS Settings app → Skyl → turn off Notifications.
- Android: Open Settings → Apps → Skyl → Notifications → turn off Allow notifications.
4.2 How to turn off Location Services
Inside the App:
- Open the Skyl app.
- Tap your profile icon, then tap Settings.
- Under Privacy, toggle off Location Services.
- When off, the App will not access your GPS. Weather is currently unavailable; when enabled, it also respects this setting, and the map will not center on your current location.
At the OS level (recommended as well):
- iOS: iOS Settings → Skyl → Location → select Never.
- Android: Settings → Apps → Skyl → Permissions → Location → Don't allow.
4.3 How to turn off Online Status (presence)
- Open the Skyl app.
- Tap your profile icon, then tap Settings.
- Under Privacy, toggle off Show Online Status.
- When off, your
last_seentimestamp is cleared and other users will not see a green/red presence dot on your profile, in the Crew list, or in direct messages. You will also stop seeing other users' online status if you have it disabled for yourself.
4.4 How to opt out of ad tracking
- iOS: After you confirm eligibility, Skyl may show an App Tracking Transparency prompt before initializing ads. Tap Ask App Not to Track to deny access to your advertising identifier. You can change this later in iOS Settings → Skyl → Tracking.
- Android: Open Settings → Ads → Reset advertising ID or Opt out of Ads Personalization.
4.5 Automated moderation permission
Before using moderated features, the updated September 22 iOS build asks you to allow content transfers to OpenAI for text safety checks and Sightengine for image/video safety checks. This can include private messages and other private content on moderated features. We record the accepted disclosure version and time. Permission is required for these features; you can decline, sign out, or delete your account without accepting. Contact us to withdraw permission; we will stop further covered transfers and explain the effect on your account. Prior transfers remain subject to applicable retention and legal requirements.
5. Data Retention
We retain your information for as long as your account is active and for a limited period afterward to meet legal, safety, and accounting obligations:
- Account data. Retained until you delete your account. After you request deletion, your login is disabled immediately and the account is fully removed within 30 days (including leftover media and any orphaned login record). Skyl also reserves the right to delete accounts that have been inactive for an extended period.
- User-generated content. Content remains until you delete it or your account, or we remove it under our Terms. Deleting a post removes its database record and queues its files for deletion. Comments and chat messages may first have their content removed while an empty record remains; scheduled cleanup removes eligible records after 90 days. An empty comment placeholder may remain while replies still depend on it. Hiding a conversation only changes your conversation list and does not delete messages.
- Messages. Direct messages and crew chats are retained until you delete them or your account is deleted.
- Push tokens. Removed when you sign out, delete your account, or disable notifications.
- Moderation records. Reports, scans, and enforcement actions are retained for up to 24 months for safety, audit, and legal-defense purposes.
- Engagement and analytics events. Aggregated and anonymized data may be retained indefinitely; identified
feed_eventsare retained for up to 24 months. - Support tickets. Retained for up to 24 months after resolution.
- Cleanup records. Retention execution logs contain counts and status. Media deletion queues also contain account identifiers, resource keys and processing status so we can safely finish deletion. Completed queue records are removed after 90 days; unresolved requests and ownership evidence remain restricted until resolved or a specific retention obligation ends.
Automated cleanup runs in batches. The periods above are our ordinary retention schedule; we review failures and outstanding work. We may preserve information longer when necessary for a specific legal obligation, dispute or safety investigation, restrict access during that period, and review the need to retain it. Provider-operated diagnostics and backups have separate lifecycle settings; active-system deletion does not immediately erase every backup copy.
6. Security
We use industry-standard safeguards to protect your information, including encrypted transport (TLS), hashed passwords (managed by Supabase Auth), row-level security policies on the database, and access controls on internal systems. However, no system is perfectly secure, and we cannot guarantee absolute security.
Session tokens (including tokens for multi-account switching) are stored on your device using AsyncStorage. We recommend using a strong device passcode and biometric lock to protect local data.
7. Age Requirement and Underage Accounts
Skyl is intended for people aged 18 or older and is not offered to anyone under 18. We record your confirmation of eligibility and the applicable policy version; we do not treat a checkbox as independent proof of age. Existing accounts must confirm the new 18+ requirement. If we learn that an account belongs to someone under 18, we will restrict access and arrange deletion, subject to legally required retention. To report an underage account or request its deletion, contact team@skylstudios.com.
The App includes child-safety moderation: content that appears to involve the sexual exploitation of minors is escalated, removed, and may be reported to the National Center for Missing & Exploited Children (NCMEC) where required by law.
8. International Users
The Service is operated from Canada. Skyl's primary data infrastructure is hosted as follows:
Our Supabase project is configured in the Canada Central region. Cloudflare delivers media through its global network. Other providers listed in section 3.2 may process information in the United States and other countries, and support, logs, backups and subprocessors may operate outside the primary hosting region. A Canadian database region does not mean all processing stays in Canada.
Information processed abroad may be subject to the laws and lawful access requirements of those countries. Contact team@skylstudios.com for information about our foreign service providers and our policies for handling information outside Canada.
8.1 Canada (PIPEDA)
Vestgaard Construction Ltd. is a Canadian organization. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Alberta law. You may request access to, correction of, or deletion of your personal information by emailing team@skylstudios.com. We will respond within 30 days. If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada or, where Alberta PIPA applies, the Office of the Information and Privacy Commissioner of Alberta.
8.2 California Consumer Privacy Act (CCPA/CPRA)
If you are a California resident, you have the right to: know what personal information we collect, request deletion, request correction, opt out of the sale or sharing of your personal information, and not be discriminated against for exercising these rights. To exercise these rights, contact team@skylstudios.com. We do not sell personal information. Where applicable, you can opt out of sale or sharing through Settings → Ad privacy or by contacting us. Apple tracking permission can also be managed in iOS Settings; it is not the only privacy control.
8.3 Other U.S. state privacy laws
If your state has a consumer privacy law (for example, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana CDPA, or others), you may have similar rights to access, correct, delete, or opt out of certain processing. To exercise these rights, contact team@skylstudios.com. We will respond within 30 days.
9. Third-Party Links and Content
The App may contain links to third-party websites or display content hosted by third parties (for example, news articles, weather data, or job postings that link to external sites). We are not responsible for the privacy practices of those third parties. This Privacy Policy does not apply to third-party services.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App or on our website and, where appropriate, sending a notification. The "Effective date" at the top of this policy indicates when it was last updated. Your continued use of the Service after a change constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:
Vestgaard Construction Ltd. (operating as Skyl)
- Mailing address: 115 Royal Birch Circle NW, Calgary, Alberta, Canada
- Email:
team@skylstudios.com
Please include a description of your request and, where relevant, the account email or user ID involved. We will respond within 30 days.
12. Summary of Data Categories
For your convenience, the categories of personal information we collect are:
- Contact info — email, phone number (account and optional display contact).
- Identifiers — user ID, username, push token, advertising identifier (when ATT granted).
- Account and profile data — name, bio, trade, location, image, banner, account type, badges, certifications.
- User-generated content — posts, comments, messages, job listings, portfolio items, club posts, feedback.
- Usage data — likes, follows, saves, post views, feed events, search history (on device).
- Location — GPS coordinates (when enabled), city cache, location text.
- Presence —
last_seentimestamp (when online status is enabled). - Device data — OS version, device model, app version, language, crash logs.
Each category is used for the purposes described in Section 2 and shared as described in Section 3.
Operated by Vestgaard Construction Ltd. · Privacy · Terms · Guidelines · team@skylstudios.com